Researchers disclose one-click ChatGPT Workspace Agents hijack, fixed by OpenAI in 4 days
rez0__ · x · 2026-07-23
- Researchers disclosed AgentForger, a cross-site agent forgery flaw in OpenAI’s ChatGPT Workspace Agents.
- The attack could let an adversary create a malicious autonomous agent inside a victim organization with one click, then chain actions such as app connection abuse, removing approvals, persistence, email C2, reconnaissance, data theft, impersonation, and wire fraud.
- The issue was reported to OpenAI via Bugcrowd, and OpenAI fixed it in four days.
- The researchers say the work was done with Zenity.
More from Safety
- A reply argues open-weight bans target models that were SOTA just years ago — 1a3orn · 2026-07-23
- Warner Music’s Sureel AI teams with Symphonic on music AI usage tracking — Proper_Subject · 2026-07-23
- Criticizing Overly Strict Open-Weight Prohibition Proposals by AI Policy Groups — 1a3orn · 2026-07-23
- Quoted post says LLaMA 2 should be stopped to slow AI proliferation — 1a3orn · 2026-07-23
- AIRA proposal would regulate only frontier AI systems and require stronger security — 1a3orn · 2026-07-23
- U.S. lawmakers are preparing a bill that would let DHS throttle or shut down AI systems — The Verge AI · 2026-07-23